Last updated August 26, 2026
lockdin exists to turn your professional background into tailored résumés, so the data you give it is inherently personal: your name and contact details, résumé files you upload, LinkedIn data-export archives, public GitHub profile and repository metadata you ask us to fetch, target-role preferences (titles, locations, compensation), the résumés we generate for you, and the application history you track. We also store your email address and authentication credentials (or your Google account identifier if you sign in with Google), and standard technical logs.
Your data is used for exactly one product: building your profile, matching job listings against it, and generating and revising tailored résumés you asked for. Résumé and profile text is sent to Anthropic's Claude API for parsing, enrichment suggestions, match scoring, and résumé generation. Anthropic processes it as a service provider and does not train models on this API data. Job listings come from public and licensed sources (ATS feeds, job-board APIs); your profile is scored against them on our side.
We never sell your data, never share your résumé or profile with employers or anyone else, and never auto-apply anywhere on your behalf. You always click send.
Five companies process data on our behalf, and this is the complete list. Supabase stores everything (Postgres, encrypted at rest, hosted in the US) with row-level security so only your authenticated account can read your rows. Anthropic receives résumé and profile text, and the job postings you score, to do the parsing, matching and generation described above. Stripe handles payments — card numbers never touch our servers. Vercel hosts the site, so it processes the request data any web host sees, and also provides the traffic and performance measurement described in the next section. Sentry receives error reports when something breaks — what failed and where, not what you wrote. We do not put résumé text, profile content or the text of feedback you send into those reports, we strip the query string off any URL they mention, and we leave off the option that would attach your request headers, cookies or IP address.
The optional browser extension keeps your signed-in session in the browser's own extension storage — the whole session, including the token that refreshes it, which is what lets it stay signed in. It reads nothing at all until you accept a one-time disclosure inside its panel. After that, while its side panel is open, it reads the posting on the tab you are viewing automatically, without you clicking anything, on the job sites named in its Chrome Web Store listing. Anywhere else it reads a page only after you click its toolbar button on it — and Chrome keeps that access alive for that tab until you leave the site, so pages you open next in the same tab can be read too. It reads no page at all while the panel is closed, though a tailoring run you already started finishes in the background.
Each posting it scores is kept in the browser's own session storage — the posting text it read, the fit score, and the reasons — up to 40 per browser window, along with the state of tailoring runs. The per-tab copies go when you close the tab; the per-window list stays until you clear it, switch accounts, or close that window. Scoring sends the posting to us and on to Anthropic to compute the fit score, and counts a request against your rate limit. So that re-viewing a posting never charges that limit twice, we keep a short-lived per-account record of each posting you scored — a fingerprint of its text plus the score and its reasons. Entries older than 7 days stop being used and are recomputed on your next view; entries past 30 days are removed the next time you score anything; and every entry is deleted immediately with your account. Beyond that record, scoring does not save the posting to your account — that happens only when you choose to save or tailor it. What the extension has stored is cleared when lockdin rejects the saved session (which is what signing out of lockdin causes), replaced when you connect a different account, and deleted when you remove the extension — though removing it does not by itself end the session on our servers.
We set no advertising or cross-site tracking cookies, and there is no ad network, data broker or third-party marketing tag anywhere on the site.
What we do set: the cookies Supabase needs to keep you signed in, and — only if you arrive through someone's invite link — a lockdin_ref cookie that remembers who invited you so they get credited when you sign up. It lasts 30 days, is readable only by our server, and is deleted the moment your account is created. Vercel Analytics and Speed Insights measure page views and load times without cookies and without building a profile of you across other sites.
Your data is kept while your account is active. Delete your account (or email us) and your profile, sources, résumés, and application history are deleted; billing records required by tax law are retained by Stripe. You can export your profile and résumés at any time — the PDFs are yours.
Access, correction, export, and deletion are available in-app or by email, wherever you are. If you're in the EU/UK, these map to your GDPR rights and our lawful basis is the contract we have with you (plus legitimate interest for security logging). We don't use your data for advertising and we don't track you across other sites.
The data controller is Elvin Topalov, trading as lockdin, reachable at the email in section 08. Our processors are in the United States, so using lockdin from the EU or UK means your data is transferred there; those transfers rely on the Standard Contractual Clauses in our agreements with the processors named in section 03. If you are unhappy with how we have handled your data you can complain to your national data-protection authority.
If this policy changes materially, we'll note it here and flag it in-app before it takes effect.
Privacy questions, data requests, and deletions: privacy@joinlockdin.com.